BeeraSafe

Understanding findings and severity

What a finding record contains, what each severity means, and how the triage lifecycle works.

Last updated · September 2026

On this page

Each finding is a structured record describing a single security concern, with a lifecycle: open, in progress, ignored, resolved, or accepted risk. Findings carry CVE identifiers and CVSS scores where advisories publish them.

Severity levels

LevelMeaningExamples
CriticalDirectly exploitable with high impact.RCE via unsafe deserialization, critical CVE with a public exploit, exposed cloud root credentials.
HighExploitable under realistic conditions with significant impact.SQL injection, high-severity dependency CVE with a fix available.
MediumRequires specific conditions or has limited impact.Verbose errors leaking internals, S3 bucket without encryption, missing rate limits.
LowBest practice violations or defense-in-depth concerns.Missing security headers, mutable image tags, informational disclosures.

Anatomy of a finding

FieldTypeDescription
severitycritical | high | medium | lowRisk classification from CVSS and exploitability context.
cvestring | nullCVE identifier from the advisory, when published.
cvssnumber | nullCVSS base score from the advisory, when published.
packagestring | nullAffected package and installed version for dependency findings.
fixVersionstring | nullFirst patched version, when the advisory names one.
filestring | nullRelative path for code, secret, and IaC findings.
linenumber | nullLine number where the issue begins, if identifiable.
statusopen | in_progress | ignored | resolved | accepted_riskTriage lifecycle state. People change it, never silently.